Glossary

What is Data Controller?

A data controller is the natural or legal person who determines the purposes and means of processing personal data and manages the data recording system, under Article 3 of the KVKK. It corresponds to the controller concept in Article 4 of the GDPR. A company operating a website and collecting visitor data is the controller of that data.

Article 3 of the KVKK defines the data controller as the natural or legal person who determines the purposes and means of processing and is responsible for establishing and managing the data recording system. The decisive question is: who decides why and how this data is processed? Whoever makes that decision is the controller. In companies, the responsibility sits with the legal entity itself, not with employees or departments. A party processing data on the controller's behalf and instructions, such as a hosting or email provider, holds the separate role of processor. The GDPR draws the same distinction in Article 4.

Being a controller brings concrete duties: relying on one of the processing conditions in Article 5 of the KVKK, informing individuals under Article 10, obtaining explicit consent where needed, implementing security measures, answering data subject requests and, where applicable, registering with VERBIS. In a website context, the controller is usually the company operating the site: form submissions, account records and identifiers collected through cookies fall under its responsibility. Using tools like Google Analytics does not shift that responsibility away, because the decision to add the tool and define its purpose belongs to the site owner.

Frequently asked questions

What is the difference between a data controller and a data processor?

The controller decides why and how data is processed; the processor is a separate natural or legal person processing data on the controller's behalf, based on the authority the controller grants and in line with its decisions. For example, an e-commerce site is the controller of its customer data, while its hosting provider or email delivery service is a processor. The primary obligations stay with the controller.

Is a website owner always the data controller?

If personal data is collected through the site and the site owner defines its purpose, then yes: for form data, accounts and cookie identifiers, the owner is the controller. Using third-party tools does not remove that role, since the decision to add a tool and set its purpose belongs to the owner. Who holds which role should be clarified by looking at each tool's actual data processing setup.

This content is for information only and is not legal advice.